Nine Elms Florist Privacy Statement
Privacy Policy for Customers Ordering from Nine Elms Florist
This Privacy Policy describes how your personal information is collected, used, and protected by Nine Elms Florist. It applies to all customers placing orders with us from Nine Elms and the surrounding districts. We are committed to safeguarding your privacy in line with the General Data Protection Regulation (GDPR).
1. What Personal Data We Collect
When you place an order with Nine Elms Florist, we collect and process the following types of personal data:
- Contact information: Name, delivery address, billing address, telephone number (if provided).
- Order details: Order contents, delivery preferences, special instructions, and notes attached to your order.
- Payment information: We may process limited payment method details (such as card type, last four digits of a card number). However, full payment information is managed by our third-party payment processors and not stored by Nine Elms Florist.
- Recipient details: If you order flowers for someone else, we may collect the recipient's name, delivery address, and contact information as required to complete the delivery.
- Communication data: Records of your communications and correspondence with us, such as email messages, feedback forms, or telephone calls.
- Website usage information: Automatically collected technical data such as IP address, browser type and version, session information, and your interactions with our website to improve our services.
2. Lawful Basis for Processing
Under GDPR, we rely on the following legal bases for processing your data:
- Contractual Necessity: Most data we collect is used to fulfill your order and deliver flowers to you or your chosen recipient. Without this information, we cannot provide our services.
- Legitimate Interests: We may process data to enable us to improve our products and services, respond to queries, and keep records to manage our business efficiently, provided that your rights and freedoms are not overridden.
- Legal Obligations: We may need to retain certain transactional records for purposes of compliance with applicable financial and tax laws.
- Consent: Where required (for example, for marketing communications), we will seek your consent prior to processing your personal data for those purposes. You may withdraw consent at any time.
3. How We Use Your Personal Data
Your data is used solely for purposes connected to the fulfillment and management of your order and to enhance your customer experience. Specific purposes include:
- Processing and delivering your flower order.
- Contacting you regarding your order status, delivery issues, or customer support requests.
- Improving our products, website, and services based on aggregated usage information and feedback.
- Fulfilling legal and regulatory requirements.
- If you have consented, sending informational updates and promotional offers.
4. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy:
- Order and account information: typically kept for up to six years after your last transaction to comply with legal and accounting requirements.
- Recipient details: retained as part of your order record but not used for any purpose beyond order delivery.
- Marketing preferences: retained until you withdraw consent or request erasure, unless required by law to retain proof of consent withdrawal.
- Website analytics (anonymized data): may be retained for statistical analysis without limitation, but this does not identify you personally.
5. Data Sharing and Processors
We will never sell your personal data. However, to fulfill your order and operate our business, we may share your data with trusted third-party service providers (data processors) who perform functions on our behalf, including:
- Payment processing companies to manage secure transactions.
- Local couriers and delivery partners to deliver your order accurately and efficiently.
- IT and website hosting providers to ensure reliable online services and data security.
- Accountants and auditors for compliance with financial regulations.
We require all processors to maintain appropriate security and confidentiality and not to use your information for their own purposes.
6. International Data Transfers
Your personal data is typically processed and stored within the United Kingdom or the European Economic Area (EEA). If we need to transfer your data outside the EEA, we will ensure adequate safeguards are in place in accordance with GDPR requirements.
7. Your Rights Under GDPR
Under GDPR, you have several important rights in relation to your personal data:
- Right of Access: You can request confirmation of whether we hold personal data about you and access to that information.
- Right to Rectification: You may request that inaccurate or incomplete data be corrected.
- Right to Erasure: You can request deletion of your data where there is no lawful reason for us to continue to process it.
- Right to Restrict Processing: You may restrict how we process your data in certain circumstances.
- Right to Data Portability: You can request to receive your personal data in a commonly used and machine-readable format, or transmit it directly to a third party.
- Right to Object: You can object to the processing of your data where we are relying on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where consent is required, you have the right to withdraw it at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
To exercise any of these rights, please contact us using the details provided on our website or in your order documentation.
8. Data Security
We employ suitable physical, electronic, and managerial procedures to safeguard and secure your information. Access is limited to authorized personnel and trusted providers who require it in order to process your order and manage our services.
9. Policy Updates and Review
We regularly review and update this Privacy Policy to reflect changes in our practices or legal requirements. The latest version will always be available on our website. We encourage you to review it periodically to ensure you remain informed.
10. Scope of this Privacy Policy
This Privacy Policy applies to all customers of Nine Elms Florist placing orders from Nine Elms and surrounding districts. By placing an order with us, you acknowledge the practices described in this document and consent to our processing of your personal data as described.